Legal
Terms of service
The general terms under which AxisOne Group SL provides attendo to businesses and professionals. Each customer’s proposal or contract completes them, setting the modules, users, price and service levels.
Scope and parties
These terms govern how AxisOne Group SL (“we”), whose details appear in the legal notice, provides attendo, a platform for managing data, communications and processes, to the business or professional that subscribes to it (“the customer”).
attendo is provided as a cloud service (SaaS): it is not installed on the customer’s systems. Data is hosted in the European Union, in a separate database for each customer. As a project, attendo can also be installed on the customer’s infrastructure (on-premise); in that case, installation, licensing, updates and data processing are governed by the project contract.
attendo is only available for business or professional use. By accepting these terms, the customer confirms that it acts in that capacity, so consumer protection law does not apply.
Contract documents
The contract consists of the following, in this order of precedence:
- the proposal or specific contract the customer accepts, with the modules, users, price, term and service levels;
- the data processing agreement, which prevails in everything related to personal data;
- these general terms.
We make these terms available to the customer before subscribing, and the customer can save and print them. They are available in Spanish and English; if they differ, the Spanish version prevails.
Subscription, setup and account
The subscription is formalized when the customer accepts the proposal or signs the contract. We then set up the customer’s attendo instance and send access to the administrators it designates.
The customer is responsible for providing accurate data and keeping it up to date, managing its users, profiles and permissions, and keeping credentials safe. Each user account is personal. The customer is responsible for what is done with its accounts and will tell us as soon as it knows of or suspects unauthorized access.
attendo offers two-factor authentication, which the customer can make mandatory by profile, sign-in with Microsoft, Google or Auth0, and a password policy. We recommend turning them on.
Trial account
If the customer requests a trial account through the website, someone from our team sets it up with the modules of the chosen solution and emails the access details. It is for evaluating attendo, not for production use, and lasts for the period we state when opening it.
The trial account is provided as is, with no availability or support commitment beyond what is reasonable for the evaluation. When it ends, if the customer does not subscribe, we delete the instance and its data. These terms, including acceptable use and data, apply during the trial.
Modules, configuration and integrations
attendo is modular. The proposal or contract sets the modules, features, number of users and integrations that are turned on. The customer can ask to turn modules on or off during the contract, under the terms of the proposal.
We improve and update attendo continuously. Updates do not touch the customer’s configuration (document types, fields, screens, flows and templates). If a change removes a feature the customer relies on, we will give reasonable advance notice.
Integrations with third-party services that the customer turns on (its ERP, email, WhatsApp, AI provider or maps, among others) work with the customer’s own account and credentials in that service, which is governed by its own terms. We are not responsible for changes to or interruptions of those services.
Portals
Documentation for the coordination of business activities
The supplier portal lets the customer ask its suppliers and subcontractors for the documentation it considers necessary for the coordination of business activities (occupational health and safety), receive it, review it and see its expiry date. attendo alerts the customer and the supplier before a document expires.
attendo is a document management tool. It does not check the authenticity, actual validity or content of the documents, does not assess whether they are sufficient and does not certify compliance with article 24 of Spanish Law 31/1995 of 8 November on the Prevention of Occupational Risks or with Royal Decree 171/2004 of 30 January. Those obligations, and the decisions taken with the documentation, rest with the customer and its suppliers.
A document that is expired, rejected or not submitted is flagged on the supplier’s record, but does not prevent work from being assigned to that supplier. Deciding whether a supplier can work at a site with the documentation it has submitted is up to the customer.
The documentation may contain personal data of the supplier’s workers. The customer will only ask for the documents needed for coordination, will decide how long it keeps them and will limit which users can see them. attendo processes that data as the customer’s processor, under the section “Customer data and data processing”.
The customer will not ask for medical reports or diagnoses. For health surveillance, the fitness-for-work conclusion permitted by article 22.4 of the Law on the Prevention of Occupational Risks is enough.
When giving its suppliers access to the portal, the customer will inform them that it is the controller of the data they upload and of the purpose for which it uses that data.
Signature of the service recipient collected by a supplier
If the customer turns it on, its suppliers can collect, on their own device, the signature of the person receiving the service in order to close the work order. The signature is attached to the document with its date and time, and the document cannot be modified once signed.
It is a simple electronic signature within the meaning of Regulation (EU) 910/2014 (eIDAS). It shows that the signer agrees with the work order shown to them. It is not an advanced or qualified electronic signature, and its value as evidence is assessed under article 25 of that Regulation and the applicable procedural law.
The supplier collects the signature on the customer’s behalf and following its instructions. It must show the signer the full work order before they sign, may not sign in their place and may not change the work order once signed. The supplier is answerable to the customer for its use of this feature.
The customer decides which suppliers can collect signatures and what value it gives those signatures towards its own clients.
The signer’s name and signature are personal data for which the customer is the controller. attendo processes them as a processor. The supplier only accesses them to collect the signature and may not use them for its own purposes.
Partners
The customer can give access to the partner portal to companies that serve its clients or act on their behalf, such as insurers, property managers or distributors. For each client in a partner’s portfolio, the customer sets which documents the partner sees, what it can do on the client’s behalf, whether it can access the personal data on the client’s record and who receives communications: the client, the partner or both. attendo records who grants each access and when.
Before giving a partner access, the customer will determine, for each relationship, the partner’s role in processing the data: the customer’s processor, joint controller or controller receiving the data on its own legal basis. The customer will formalize this with the partner in the appropriate agreement under articles 26 or 28 of Regulation (EU) 2016/679. attendo is not a party to that relationship.
The customer will give each partner access only to the data it needs for its role. By default, the partner sees the minimum data of each client; access to the rest of the personal data on the record has to be turned on expressly.
If a client’s communications are sent only to the partner, the customer guarantees that the client has been informed, directly or through the partner, that its communications reach it through the partner and of who processes its data.
If the partner uses its own brand towards its clients, the customer and the partner will make sure that the data protection information identifies the controllers. The brand does not change the role the customer has set for the partner.
When the customer suspends or ends a relationship, the partner stops accessing that client’s data. Anything the partner has downloaded outside attendo is governed by the agreement between the customer and the partner.
Obligations of the parties
AxisOne Group SL agrees to:
- provide the service with the diligence of a professional provider and according to the proposal or contract;
- maintain the technical and organizational security measures described in the data processing agreement;
- provide support through the agreed channels and hours;
- give reasonable advance notice of scheduled maintenance;
- process customer data only as a processor.
The customer agrees to:
- use attendo in accordance with these terms and the law;
- pay the price on the agreed dates;
- manage its users and keep credentials safe;
- have a legal basis for the data it processes in attendo and inform the people concerned;
- configure integrations and permissions correctly;
- cooperate during onboarding with the data, access and approvals needed.
Acceptable use
The customer and its users may not use attendo to:
- carry out unlawful activities or infringe third-party rights, including intellectual property and data protection;
- send unsolicited marketing by email, WhatsApp, SMS or phone, or run campaigns without the required legal basis;
- store or distribute unlawful, defamatory or discriminatory content, or content that incites violence;
- introduce malicious software, attack or probe the platform, or bypass its technical or security limits;
- resell attendo or give access to third parties outside its organization without permission, except for the access of its clients, suppliers and partners to the portals intended for them;
- reverse engineer it, except as permitted by law, or use the platform to build a competing product;
- use it in a way that degrades the service for other customers, such as bulk automated loads outside the API.
If we detect use that breaches these terms, we will ask the customer to fix it. If it is serious or puts the platform, other customers or third parties at risk, we may proportionately suspend the affected access, explaining the reasons to the customer and how to appeal.
Illegal content and point of contact
If you see content you consider illegal on a portal, web quote or form published with attendo, report it to sales@attendo.me, stating the exact address where it is, why you consider it illegal, and your name and email. We will review it diligently, notify the customer that published it and tell you what we decided.
The single point of contact for authorities and recipients of the service (articles 11 and 12 of Regulation (EU) 2022/2065, the Digital Services Act) is sales@attendo.me, in Spanish or English.
Customer data and data processing
The data the customer stores in attendo belongs to the customer. We only process it to provide the service, give support and comply with the law. We do not sell it or use it for our own purposes.
For personal data, the customer is the controller and AxisOne Group SL is the processor. The data processing agreement (GDPR art. 28) is part of these terms and covers, among other points:
- the subject matter, duration, nature and purpose of the processing, the types of data and the categories of data subjects;
- processing only on the customer’s documented instructions;
- the confidentiality duty of authorized personnel;
- the security measures of GDPR article 32;
- the conditions for engaging sub-processors, with their list and prior notice of changes so the customer can object;
- assisting the customer with data subject requests and with its obligations on security, breach notification, impact assessments and prior consultations;
- notifying personal data breaches affecting its data without undue delay;
- returning or deleting the data at the end of the service, at the customer’s choice;
- providing the information needed to demonstrate compliance and cooperating with audits.
When the customer turns on integrations or AI providers outside the European Union, the data they need goes to them by the customer’s decision and under those providers’ terms.
Portal users (the customer’s clients, suppliers and partners) access data with the permissions, scope and conditions the customer configures. attendo does not give access to any third party on its own initiative, and processes the data those users see or provide as the customer’s processor.
Artificial intelligence
marIA is the attendo AI. It works with the AI provider the customer chooses (including OpenAI, Google Gemini, Anthropic, Mistral, Scaleway, Microsoft 365 Copilot or OpenRouter), with the customer’s key and under that provider’s terms, or with attendo AI credits on Scaleway.
marIA proposes and a person decides. Anything sent to a customer or third party waits for a user’s approval by default. Exceptions, such as some automatic replies, are off by default and can only be turned on by one of the customer’s administrators, who takes responsibility for their use.
AI output may contain errors. The customer must review it before using it and is responsible for the decisions it makes with it. Every operation is logged with its user, model and cost, and the customer sets a monthly budget that stops spending when reached.
attendo does not train or fine-tune artificial intelligence models on customer data. Whatever marIA needs to know about the customer, it reads from the customer’s documents and settings in each operation, without incorporating it into any model. How each AI provider uses the data it receives is governed by that provider’s terms, which the customer accepts by choosing it.
When the customer uses AI features that interact directly with people, such as the website chatbot or voice bots, it will tell those people that they are dealing with an AI system when this is not obvious, as required by article 50 of Regulation (EU) 2024/1689, the AI Act.
Providers authorized for customer data
marIA features that read records from the customer’s tables (operations, contacts and users) only send them to AI providers authorized for customer data, which are listed as such in the list of sub-processors. Other providers only receive the necessary structure and configuration (field names and types, instructions) and the text of the document the user is working on.
Prioritize with AI
If the customer turns on AI prioritization of its pending items, attendo sends to the authorized provider chosen by the administrator, for each pending document, its subject, type, status, amounts, key date and an excerpt of its latest messages. For each message it only states whether it was written by the client or by the company. It does not send the agent’s name, the client’s name or attachments. The text of the messages may contain names or other personal data.
The AI orders documents by urgency. It does not assess, rank or compare people. The order is a proposal and the decision is the user’s.
If the customer uses prioritization to organize its staff’s work, it will comply with the duty to inform the workers’ legal representatives of the parameters and rules of the system set out in article 64.4.d of the Spanish Workers’ Statute.
Maintenance KPI chat
The maintenance KPI chat sends to the AI provider configured for it the user’s questions and a summary of the maintenance KPIs for the last 90 days. The summary contains aggregated figures and the names of the plants, assets, plans and clients that appear in those KPIs. It does not contain individual records.
The customer decides which provider handles the chat. If it does not want those names to reach a provider that is not authorized for customer data, it will configure an authorized provider for the chat or not turn it on.
AI activity log
attendo logs every AI operation with its user, model, cost and date. The content sent to the provider and the response received are kept for 90 days so the customer can review them; after that they are deleted and only the operation details are kept.
Availability, support and backups
We work to keep attendo available at all times, except for scheduled maintenance, which we announce in advance, and causes beyond our control. Specific availability levels, support response times and support hours are set in the proposal or contract.
Support is provided through the agreed channels, including the support form on the website.
We back up customer data. The customer can also download backups whenever it wants and schedule a backup to its own S3 storage.
Price and billing
The price, payment method and price updates are set in the proposal or contract. Unless otherwise agreed, amounts do not include taxes.
If the customer does not pay on time, we may, after written notice, suspend the service until payment is made. Suspension does not affect the customer’s data.
Intellectual property
attendo, its software, design, documentation and trademarks belong to AxisOne Group SL or its licensors. The customer receives a non-exclusive, non-transferable right to use it during the contract, for its organization and on the agreed terms.
The customer’s data and content belong to the customer. The customer authorizes us to process them only as needed to provide the service.
Configurations, templates and developments we build for the customer are governed by its proposal. Unless otherwise agreed, general improvements to the platform remain ours. If the customer suggests improvements, we may add them to attendo without using its confidential information.
Confidentiality
Each party will keep secret the other’s confidential information it learns through the contract (data, prices, processes and technical or security documentation) and use it only to perform the contract. This obligation lasts for the term of the contract and five years after, and does not apply to public information, information already known, or information that must be disclosed by law or by order of an authority.
Term, renewal and termination
The contract lasts for the initial period set in the proposal and renews for equal periods, unless either party gives notice of non-renewal within the agreed notice period.
Either party may terminate the contract if the other seriously breaches its obligations and does not cure the breach within 30 days of written notice.
On termination, access is closed and the data return provisions apply.
Portability, data return and switching providers
The customer can export all its data at any time during the contract, in structured, commonly used and machine-readable formats, and also through the API.
When the contract ends, we keep the data available for the customer to download for at least 30 days. After that we delete it securely, including from backups as their cycles expire, except what the law requires us to keep.
The customer may request switching to another provider or to its own systems with a maximum notice period of two months, as provided in Regulation (EU) 2023/2854, the Data Act. We will cooperate in good faith during a transition period of up to 30 days, keep the service and security running throughout, and provide the information needed for the switch. Any switching charges follow article 29 of that Regulation.
The infrastructure we use to provide attendo is located in the European Union and subject to its jurisdiction. The measures to prevent international governmental access to non-personal data that would conflict with EU law are described in the security documentation we provide when subscribing (Data Act art. 28).
Liability
Each party is liable for the damage it causes by breaching the contract. Except in cases of willful misconduct or gross negligence, or where the law does not allow limitation, the total liability of AxisOne Group SL under the contract is limited to the amount paid by the customer in the twelve months before the event giving rise to it, and neither party is liable for lost profits, loss of business or indirect damages.
We are not liable for third-party services the customer integrates, for the content and data it stores, for the use of unreviewed AI output, or for interruptions caused by force majeure or by causes beyond our reasonable control.
Changes
We may change these terms to adapt them to legal, technical or service changes. We will notify customers at least 30 days in advance, by email or on the platform. If the change significantly harms the customer, it may terminate the contract before the change takes effect, without penalty. Changes required by law may apply within the period the law sets.
Contract communications are made in writing, to the email addresses each party designates.
Governing law and jurisdiction
These terms and the contract are governed by Spanish law. Before going to court, the parties will try to settle any dispute through negotiation. If they cannot, they submit to the courts of Barcelona, waiving any other venue.